AMD Acknowledges TPM Vulnerability Affecting Ryzen 3000–9000 Series, Patches Available
Quick Report
AMD disclosed a critical TPM 2.0 vulnerability affecting Ryzen processors from the 3000 to 9000 series, discovered by Intel security researchers and now fully patched. The out-of-bounds read vulnerability (CVE-2026-6726, CVSS 8.5) could allow attackers to bypass TPM functionality and compromise digital signing and encryption.
Motherboard vendors have been distributing patches since May 2026, with additional updates rolling out through June and July. Remaining CPU families such as Ryzen AI 300, Ryzen AI 400, and Ryzen AI Max 300 series will receive their Pluton secure processor updates in August. Intel security researchers, the Trusted Computing Group, and AMD coordinated the response to ensure timely patching before public disclosure—a model that prevents exploitation while addressing the flaw comprehensively.
Written using GitHub Copilot GPT-5 mini in agentic mode instructed to follow current codebase style and conventions for writing articles.
Source(s)
- TPU